Last Updated: February 10, 2026
Omex Rent A Car is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, share, and protect information about you when you use our car rental services and website.
1. Information We Collect
We collect information that you provide directly to us, information we obtain automatically when you use our services, and information from other sources.
1.1 Information You Provide
- Personal Information: Name, email address, phone number, postal address, date of birth
- Driver's License: License number, issuing country, expiration date
- Payment Information: Credit/debit card details, billing address
- Rental Information: Pickup and return locations, dates, vehicle preferences
1.2 Information Collected Automatically
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, links clicked, search queries, time spent on pages
- Location Data: GPS location, Wi-Fi access points (with your permission)
- Cookies and Tracking: We use cookies, pixels, and similar technologies to track your activity
2. Legal Basis for Processing (GDPR Article 13)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal information based on the following legal grounds:
2.1 Contract Performance (GDPR Article 6(1)(b))
We process the following data to fulfill our contractual obligations to you:
- Reservation processing and management
- Vehicle pickup and return coordination
- Customer service and support
- Booking confirmations and rental documentation
- Payment processing
Data processed: Name, contact information, driver's license details, payment information, rental preferences, pickup/return dates and locations.
2.2 Legitimate Interests (GDPR Article 6(1)(f))
We process data for our legitimate business interests, which include:
- Fraud prevention and security monitoring
- Business analytics and service improvement
- Website functionality and performance optimization
- Internal record-keeping and administration
- Protecting our legal rights and interests
Data processed: Device information, IP addresses, usage data, transaction records, communication records.
We have assessed that these interests are not overridden by your data protection rights.
2.3 Consent (GDPR Article 6(1)(a))
We process the following data only with your explicit consent:
- Marketing communications (emails, SMS, promotional offers)
- Non-essential cookies (analytics, advertising, personalization)
- Location tracking beyond what's necessary for service delivery
- Sharing data with third-party marketing partners
Data processed: Email address, phone number, browsing behavior, location data, marketing preferences.
You may withdraw your consent at any time through your account settings, the unsubscribe link in marketing emails, or by contacting us directly.
2.4 Legal Obligations (GDPR Article 6(1)(c))
We process data to comply with legal requirements:
- Tax reporting and financial record-keeping
- Response to law enforcement requests
- Compliance with traffic and vehicle regulations
- Anti-money laundering requirements
Data processed: Transaction records, identification documents, rental agreements, payment records.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Processing and managing your car rental reservations (Contract Performance)
- Providing customer service and support (Contract Performance)
- Sending booking confirmations (Contract Performance)
- Processing payments and preventing fraud (Contract Performance & Legitimate Interests)
- Personalizing your experience and providing recommendations (Legitimate Interests)
- Sending marketing communications (Consent)
- Improving our website, services, and customer experience (Legitimate Interests)
- Complying with legal obligations and enforcing our terms (Legal Obligations)
- Analyzing usage patterns and conducting research (Legitimate Interests)
4. Cookies and Tracking Technologies
We use various technologies to collect information about your use of our website.
4.1 Types of Cookies
Essential Cookies (Always Active)
- Purpose: Required for the website to function properly, including security, authentication, and basic navigation
- Legal Basis: Legitimate Interests (GDPR Article 6(1)(f)) - necessary for website operation
- Examples: Session management, security tokens, load balancing
- Cannot be disabled: These cookies are strictly necessary for core website functionality
Performance/Analytics Cookies (Require Consent)
- Purpose: Help us understand how visitors use our website through analytics
- Legal Basis: Consent (GDPR Article 6(1)(a))
- Examples: Google Analytics, Microsoft Clarity, Hotjar
- Can be disabled: These cookies will only be set after you provide explicit consent
Functional Cookies (Require Consent)
- Purpose: Remember your preferences and personalize your experience
- Legal Basis: Consent (GDPR Article 6(1)(a))
- Examples: Language selection, currency preferences, recently viewed vehicles
- Can be disabled: You can opt out of these cookies through our consent banner
Advertising Cookies (Require Consent)
- Purpose: Used to deliver relevant advertisements based on your interests
- Legal Basis: Consent (GDPR Article 6(1)(a))
- Examples: Google Ads, Facebook Pixel, remarketing tags
- Can be disabled: You can reject advertising cookies through our consent banner
4.2 Cookie Consent Mechanism
For EEA, UK, and Swiss Users:
When you first visit our website, you will see a cookie consent banner that blocks all non-essential cookies until you make a choice. Here's how our consent system works:
- Initial Banner Display: Upon your first visit, we display a cookie consent banner that prevents non-essential cookies from loading until you make a selection.
- Your Choices:
- Accept All: Grants consent for all cookie categories (essential, analytics, functional, and advertising)
- Customize Settings: Opens detailed preferences where you can enable/disable individual cookie categories
- Reject Non-Essential: Only essential cookies will be used (implied if you close the banner without accepting)
- Technical Implementation:
- Before consent, only essential cookies necessary for basic website functionality are set
- Analytics cookies (Google Analytics, Microsoft Clarity, Hotjar) load only after you grant consent
- Advertising cookies (Google Ads, remarketing pixels) load only after you grant consent
- Your consent choice is stored in a cookie named "UserConsent" for 365 days
- Managing Your Preferences:
- You can manage cookies through your browser settings, though this may affect website functionality
- Withdrawing consent will immediately stop non-essential cookies from processing new data, though historical data already collected under previous consent remains valid
For Non-EEA Users:
Users outside the EEA may see a simplified cookie notice. While we respect all users' privacy, the consent requirements may differ based on local laws in your jurisdiction.
4.3 Analytics Tools
Microsoft Clarity
We use Microsoft Clarity to understand how users interact with our website through behavioral metrics, heatmaps, and session recordings. This helps us improve our services and user experience.
- Legal Basis: Consent (GDPR Article 6(1)(a))
- Data Collected: Device information, browser information, cursor movements, clicks, scrolling behavior
- Third-Party Sharing: Data is processed by Microsoft Corporation
- Retention: Session recordings are retained for 30 days
- Privacy Policy: Microsoft Privacy Statement
- Activation: Only loads after you provide explicit consent through our cookie banner
Hotjar
We use Hotjar to better understand user needs and optimize our service. Hotjar collects data on user behavior to help us improve website usability.
- Legal Basis: Consent (GDPR Article 6(1)(a))
- Data Collected: Device information, browser information, geographic location (country only), interaction data
- Third-Party Sharing: Data is processed by Hotjar Ltd.
- Retention: Hotjar data is stored in a pseudonymized user profile
- Privacy Policy: Hotjar Privacy Policy
- Activation: Only loads after you provide explicit consent through our cookie banner
Google Analytics
We use Google Analytics to measure website traffic and usage patterns.
- Legal Basis: Consent (GDPR Article 6(1)(a))
- Data Collected: Pages viewed, time on site, traffic sources, device information
- Third-Party Sharing: Data is processed by Google LLC
- IP Anonymization: We have enabled IP anonymization to protect user privacy
- Privacy Policy: Google Privacy Policy
- Activation: Only loads after you provide explicit consent through our cookie banner
5. How We Share Your Information
We may share your information in the following circumstances:
5.1 Service Providers
We share information with trusted vendors who perform services on our behalf:
- Payment Processors: To process credit card transactions and prevent fraud
- Cloud Hosting Providers: To store data and operate our website infrastructure
- Email Service Providers: To send booking confirmations and communications
- Analytics Providers: Microsoft (Clarity), Hotjar, Google (Analytics) - only after consent
- Customer Support Tools: To manage support tickets and customer inquiries
Legal Basis: Contract Performance (for essential services), Legitimate Interests, or Consent (for analytics/marketing services)
Data Protection: All service providers are contractually obligated to protect your data and use it only for specified purposes.
5.2 Business Partners
We may share information with:
- Insurance Providers: To facilitate insurance coverage for your rental (with your consent)
- GPS/Navigation Services: If you opt for GPS equipment in your rental vehicle
- Roadside Assistance: In case of vehicle emergencies or breakdowns
Legal Basis: Contract Performance or Consent
5.3 Legal Requirements
We may disclose information when required by law:
- Court orders or legal processes
- Government or regulatory requests
- Law enforcement investigations
- Protection of our rights, property, or safety
- Prevention of fraud or illegal activity
Legal Basis: Legal Obligations (GDPR Article 6(1)(c)) or Legitimate Interests (GDPR Article 6(1)(f))
5.4 Business Transfers
In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. You will be notified via email and/or prominent notice on our website of any such change in ownership.
Legal Basis: Legitimate Interests (GDPR Article 6(1)(f))
5.5 With Your Consent
We may share information for other purposes with your explicit consent, such as:
- Sharing testimonials or reviews (with your permission)
- Participating in partner promotions or programs
- Referral programs
Legal Basis: Consent (GDPR Article 6(1)(a))
6. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your jurisdiction.
6.1 Transfers from the EEA/UK/Switzerland
Azerbaijan does not have an adequacy decision from the European Commission. When we transfer personal data from the EEA, UK, or Switzerland to Azerbaijan or other third countries, we implement appropriate safeguards to protect your information.
Your Rights:
You have the right to request information about the specific safeguards applied to your data transfers and details about the countries where your data is processed.
To request this information, please contact us at info@omex.az with "Data Transfer Information" in the subject line.
6.2 Transfers to Service Providers
Some of our service providers are located in countries with adequate data protection (e.g., EU member states, UK). For providers in other countries (e.g., United States), we implement appropriate technical and organizational safeguards:
- Microsoft (Clarity): US-based
- Google (Analytics, Ads): US-based
- Hotjar: EU-based (Malta)
- Payment Processors: Varies by provider
7. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information.
7.1 GDPR Rights (European Economic Area, UK, and Swiss Users)
Right to Access (Article 15)
- Request copies of your personal data
- Receive information about how we process your data
- How to Exercise: Email info@omex.az with "Access Request" in the subject line
- Response Time: Within 30 days (may be extended to 60 days for complex requests)
Right to Rectification (Article 16)
- Request correction of inaccurate or incomplete data
- Update your personal information in your account settings
- How to Exercise: Email info@omex.az or update directly in your account
- Response Time: Within 30 days
Right to Erasure / "Right to be Forgotten" (Article 17)
- Request deletion of your personal data when:
- Data is no longer necessary for the purposes it was collected
- You withdraw consent and no other legal basis exists
- You object to processing and no overriding legitimate grounds exist
- Data was unlawfully processed
- Erasure is required by legal obligation
- Limitations: We may retain data if required for legal compliance, defending legal claims, or other lawful purposes
- How to Exercise: Email info@omex.az with "Deletion Request" in the subject line
- Response Time: Within 30 days
Right to Restrict Processing (Article 18)
- Request limitation of how we process your data when:
- You contest the accuracy of the data (during verification period)
- Processing is unlawful but you don't want erasure
- We no longer need the data but you need it for legal claims
- You've objected to processing (pending verification of our legitimate grounds)
- How to Exercise: Email info@omex.az with "Restriction Request" in the subject line
- Response Time: Within 30 days
Right to Data Portability (Article 20)
- Request transfer of your data to another organization
- Receive your data in a structured, commonly used, machine-readable format (e.g., CSV, JSON)
- Applies to: Data processed based on consent or contract, and processed by automated means
- How to Exercise: Email info@omex.az with "Portability Request" in the subject line
- Response Time: Within 30 days
Right to Object (Article 21)
- Object to processing of your personal data when:
- Processing is based on legitimate interests (including profiling)
- Processing is for direct marketing purposes
- Direct Marketing: You have an absolute right to opt-out at any time
- Other Processing: We will stop processing unless we demonstrate compelling legitimate grounds that override your interests
- How to Exercise: Click "unsubscribe" in marketing emails, or email info@omex.az with "Objection" in the subject line
- Response Time: Immediate for marketing; within 30 days for other processing
Right to Withdraw Consent (Article 7(3))
- Withdraw consent at any time where processing is based on consent
- Examples: Marketing emails, non-essential cookies, optional data sharing
- Effect: Does not affect the lawfulness of processing before withdrawal
- How to Exercise:
- Marketing: Click "unsubscribe" in emails
- Cookies: Use "Cookie Settings" link in website footer
- Other: Email info@omex.az
- Response Time: Immediate
Right to Lodge a Complaint
- File a complaint with your local data protection authority if you believe we've violated GDPR
- EU Data Protection Authorities: List available here
- UK: Information Commissioner's Office (ICO) - https://ico.org.uk/
- You can still contact us first: We encourage you to contact us directly so we can address your concerns
7.2 CPRA Rights (California Residents)
The California Privacy Rights Act (CPRA), effective January 1, 2023, provides California residents with the following rights:
Right to Know (CPRA §1798.100)
- Request information about personal data we collect, use, and disclose
- Categories of personal information collected
- Sources from which information was collected
- Business purposes for collection
- Categories of third parties with whom we share information
- Specific pieces of information we've collected about you
- How to Exercise: Email info@omex.az with "California Know Request" in the subject line
- Response Time: Within 45 days (may be extended to 90 days)
Right to Delete (CPRA §1798.105)
- Request deletion of your personal information
- Exceptions:We may retain data if necessary for:
- Completing transactions or providing requested services
- Fraud detection and security
- Legal compliance
- Internal uses reasonably aligned with your expectations
- How to Exercise: Email info@omex.az with "California Deletion Request" in the subject line
- Response Time: Within 45 days (may be extended to 90 days)
Right to Correct (CPRA §1798.106)
- Request correction of inaccurate personal information
- How to Exercise: Email info@omex.az with "California Correction Request" in the subject line
- Response Time: Within 45 days (may be extended to 90 days)
Right to Opt-Out of Sale/Sharing (CPRA §1798.120)
- Our Practice: We do not sell your personal information for monetary consideration
- Sharing for Advertising: We may share data with advertising partners, which could be considered "sharing" under CPRA
- How to Exercise: Email info@omex.az or use "Cookie Settings" to disable advertising cookies
- Universal Opt-Out: We honor Global Privacy Control (GPC) signals
Right to Limit Use of Sensitive Personal Information (CPRA §1798.121)
Under CPRA, the following categories of your data are considered "sensitive personal information":
- Driver's License Number: We collect this to verify your identity and driving eligibility
- Payment Card Details: We collect this to process rental payments
- Precise Geolocation Data: We may collect this if you enable location services (optional)
Your Right to Limit: You have the right to direct us to limit our use of your sensitive personal information to only:
- Performing the services you reasonably expect (e.g., processing your rental)
- Ensuring security and integrity
- Short-term transient use
- Performing services on our behalf
- Verifying or maintaining quality or safety
- Purposes that do not infer characteristics about you
Our Current Use: We use sensitive personal information only for the purposes you would reasonably expect when renting a vehicle:
- Driver's license to verify identity and eligibility
- Payment details to process transactions
- Location data (if enabled) to provide navigation or roadside assistance
We do not use sensitive personal information for profiling, advertising, or other secondary purposes.
How to Exercise: If you believe we're using your sensitive information for purposes beyond what's reasonably expected, email info@omex.az with "Limit Sensitive Data" in the subject line.
Response Time: Within 45 days (may be extended to 90 days)
Right to Non-Discrimination (CPRA §1798.125)
- We will not discriminate against you for exercising your CPRA rights
- We will not:
- Deny goods or services
- Charge different prices or rates
- Provide different quality of services
- Suggest you'll receive different pricing or quality of services
Authorized Agents
- You may designate an authorized agent to make requests on your behalf
- Requirements: Provide written authorization signed by you, or power of attorney
- Verification: We may require you to verify your identity directly with us
Verification Process
- To protect your privacy, we verify your identity before fulfilling requests
- Information Requested: Email address, phone number, or recent rental confirmation number
- Matching: We match the information you provide against data we have on file
7.3 Rights for Users in Other Jurisdictions
If you are located in a jurisdiction with data protection laws not specifically mentioned above (e.g., Brazil's LGPD, Canada's PIPEDA), you may have similar rights. Please contact us to learn about your specific rights and how to exercise them.
8. Data Security
We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
Technical Measures:
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
- Data at Rest: Sensitive data stored in our databases is encrypted using AES-256 encryption
- Access Controls: Multi-factor authentication for administrative access
- Network Security: Firewalls, intrusion detection systems, and network segmentation
- Secure Development: Security testing and code reviews before deployment
Organizational Measures:
- Employee Training: Regular data protection and security awareness training for all staff
- Access Limitations: Personal data is accessible only to employees who need it to perform their duties
- Confidentiality Agreements: All employees sign confidentiality agreements
- Vendor Management: Third-party service providers must meet our security standards
- Incident Response: Documented procedures for responding to data breaches
Regular Assessments:
- Security Audits: Annual third-party security assessments
- Vulnerability Scanning: Regular scanning for security vulnerabilities
- Penetration Testing: Periodic testing to identify potential security weaknesses
- Compliance Reviews: Regular reviews of compliance with data protection regulations
Important Notice: However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information using commercially acceptable means, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
9. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
9.1 Retention Periods
Active Customer Data:
- Reservation and Rental Records: Retained for 7 years after rental completion (for legal, tax, and accounting purposes)
- Payment Information: Retained for the duration of the transaction plus 7 years (for financial record-keeping and dispute resolution)
- Communication Records: Retained for 3 years (for customer service quality and dispute resolution)
Marketing Data:
- Cookie Data: Retained as specified in Section 4 (typically 12-24 months)
- After Opt-Out: Removed from marketing lists within 10 business days
Legal and Compliance:
- Tax Records: 7 years (as required by Azerbaijan tax law)
- Accident/Incident Reports: 10 years (for insurance and legal purposes)
- Legal Disputes: Data related to legal proceedings retained until resolution plus applicable statute of limitations
9.2 Deletion Process
When we no longer need your information, we will:
- Securely Delete: Permanently delete data from our active systems and backups
- Anonymize: Remove identifying information so data cannot be linked back to you
- Destroy: Physically destroy hardware containing data when decommissioned
9.3 Your Right to Request Deletion
You may request earlier deletion of your data by exercising your rights under Section 7. However, we may retain certain information where we have a legal obligation or legitimate interest to do so.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
Minimum Age Requirement:
- You must be at least 18 years old to rent a vehicle from us
- Our website and services are designed for adults
If We Learn of Child Data Collection: If we become aware that we have collected personal information from a child under 18 without verification of parental consent, we will:
- Delete that information immediately from our servers
- Cease processing the information
- Take steps to prevent future collection
Parent/Guardian Notice: If you believe we have collected information from a child under 18, please contact us immediately at info@omex.az with "Child Privacy Concern" in the subject line. We will investigate and take appropriate action.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Notification of Changes:
- All Changes: We will update the "Last Updated" date at the top of this policy
- Major Revisions: For significant changes affecting your rights, we may also request your renewed consent where required by law (for example, through an updated cookie consent banner)
Version History: We maintain a record of previous versions of this Privacy Policy. To request access to a previous version, please contact us.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Omex Rent A Car
Email: info@omex.az
For Data Protection Inquiries: To exercise your rights or submit data protection requests, please email us with the following in the subject line:
- GDPR Rights: "Privacy Request"
- CPRA Rights: "California Privacy Request"
- General Inquiries: "Privacy Question"
Response Time:
- We respond to all privacy inquiries within 5 business days
- For formal rights requests (access, deletion, etc.), we respond within the timeframes specified in Section 7
Data Protection Officer: While we are not required to appoint a Data Protection Officer under GDPR (as we are not based in the EU), you may direct privacy concerns to our privacy team at info@omex.az.
Supervisory Authority Complaints: If you are in the EEA/UK and believe we have violated GDPR, you have the right to lodge a complaint with your local supervisory authority. However, we encourage you to contact us first so we can address your concerns directly.
13. Additional Information
13.1 Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read the privacy policies of any third-party sites you visit.
13.2 Social Media
If you interact with us on social media platforms (Facebook, Instagram, etc.), your interactions are governed by the privacy policies of those platforms in addition to this Privacy Policy.
13.3 Do Not Track Signals
Some browsers have "Do Not Track" features. Our website does not currently respond to Do Not Track signals, but we honor Global Privacy Control (GPC) signals for California users as described in Section 7.2.
13.4 Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you, except for fraud detection purposes which are necessary to protect our business and customers.
Last Updated: February 10, 2026
By using our services, you acknowledge that you have read and understood this Privacy Policy.